ICAI has trained 25 Chartered Accountants in Uttar Pradesh to assess how institutions collect, store and protect personal data. The move comes as organisations prepare for stricter data protection compliance and penalties that can reach ₹250 crore.

ICAI Expands CA Role Into Personal Data Security and Compliance Audits

The420 Correspondent
5 Min Read

Kanpur: The protection of personal data held by companies, hospitals and other institutions in Uttar Pradesh is set to receive greater scrutiny, with 25 Chartered Accountants (CAs) receiving specialised training in data protection auditing. The trained professionals are expected to assess how institutions collect, use, store and protect personal information.

The Institute of Chartered Accountants of India (ICAI) conducted specialised training on data security in Kanpur until August 10. CAs from Kanpur, Lucknow, Agra, Noida, Ghaziabad, Varanasi, Prayagraj and other cities participated in the programme. The initiative is aimed at expanding the role of CAs beyond conventional financial audits to include assessments of data protection practices.

FCRF Launches Certified AI-Powered SOC Analyst Program to Train the Next Generation of Cyber Defence Professionals

New Role for CAs in Data Security

Companies and institutions routinely hold large volumes of personal information belonging to customers, employees and other individuals. This may include names, mobile numbers, addresses and identity-related information. Any unauthorised access, misuse or leakage of such information can compromise individual privacy and create legal and financial risks for organisations.

During a data protection audit, institutions can be assessed on how personal information is collected, where it is stored, how long it is retained and under what circumstances it is used or shared. Auditors can also examine safeguards designed to prevent unauthorised access and identify weaknesses in existing data management systems.

Penalties of Up to ₹250 Crore

According to former ICAI Central Council member CA Mannu Agrawal, the Digital Personal Data Protection Act places significant responsibilities on organisations handling personal information. Companies, institutions and hospitals that fail to maintain adequate data security or suffer data breaches may face substantial penalties under the law. In serious cases, the penalty can reportedly go up to ₹250 crore.

Protection of children’s personal data has also been given special importance. Violations involving children’s data may attract penalties of up to ₹200 crore. This makes data protection particularly important for schools, hospitals, online platforms and other organisations that collect or process information relating to children.

ICAI Chairman CA Ankur Goyal said data has become an important asset in the digital economy and protecting it should not be viewed merely as a legal requirement but also as an ethical responsibility. The newly trained CAs are expected to guide organisations in creating safer digital environments and improving their compliance with data protection standards.

The provisions of the data protection framework are being implemented in phases. According to the information available, certain provisions came into effect from November 13, 2025, while the principal provisions are scheduled to become applicable from May 14, 2027. This phased implementation gives organisations additional time to strengthen their data protection systems.

Audits Can Identify Security Weaknesses

Regular data protection audits can help organisations identify vulnerabilities in their IT systems before they result in serious incidents. Audits can reveal areas where unauthorised access may be possible, whether excessive personal information is being collected and whether existing security measures are adequate.

Better monitoring and controlled handling of personal information can reduce the risk of data theft and leakage. It can also strengthen customer and employee confidence in an organisation’s digital systems.

As digital services continue to expand, the volume and importance of personal data will also increase. The involvement of trained CAs in data protection audits could therefore provide institutions with an additional layer of oversight, helping them strengthen compliance, improve data governance and build more secure digital systems.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Stay Connected